Responsibilities
About the Team As part of ByteDance's Security Department, Security BP team is not only responsible for the security and risk management of the Monetization business, but also plays an important role in connecting and building trust between the business and security team. Leveraging on various capabilities provided by the Security Department, we ensure the business and customer data are secured by providing high-quality services to the Monetization business, such as platform security, product security, business security and compliance governance. Responsibilities 1. Deep understanding of ByteDance's Global E-commerce business, including its risk landscape and how they could be attacked or abused. Conduct adversarial simulation exercises, attack attribution, and remediation of business security issues. 2. Research the latest tools and techniques employed by underground markets, collect relevant intelligence, perform traceback analysis, and conduct ongoing Red Team exercises for global e-commerce. Produce detailed reports with actionable recommendations to optimize existing security solutions. 3. Drive research and planning of cutting-edge security technologies based on business needs, establish a business security Red Team system, and develop offensive security capabilities along with Red Team tooling platforms. 4. Collaborate with multiple develop and product teams to make requirements into test plans, and develop/execute test scripts or code compliant with standards and procedures.
Qualifications
Minimum Qualifications 1. Proficient in reverse engineering for Android/iOS/web platforms, with experience countering common obfuscation, anti-debugging, and jailbreak/root detection techniques. 2. Familiar with the operational models of underground market ecosystems and various cheating methods, with substantial experience in penetration testing, data analysis, and data mining for business security and risk control. 3. Prior involvement in large-scale risk control system development, or practical experience in threat intelligence/business risk prevention, underground market analysis and countermeasures is preferred. 4. Strong data mining, summarization, and communication skills, with the ability to independently produce detailed data analysis reports and documentation. Preferred Qualifications 1. Possess penetration testing skills, or have experience in HVV (cyber defense exercises), CTF competitions, SRC vulnerability discovery, or related fields. 2. Experience in formulating risk control strategies, particularly in anti-crawler and traffic anti-fraud domains.